Jump to content

Recommended Posts

Posted

Currently trying to think my way around this -- we have quite a few older shared ipads with 32gb of storage.  Which - with all the will in the world - will not handle ios 26 plus all the apps we have on for student use.

 

i do have plans to sort them out and take some of the bigger apps (Garageband, iMovie) off to specialist iPads but they still try and update prompting messages about storage and updates.

 

Is there any way to block updates on these iPads - mosyle/jamf/ etc aren't clever enough to see the space available and decide that the ios update is too big for this machine.

Posted

I would definitely recommend not blocking updates. My inner cyber security guru shudders at the thought!

 

We have a few 8th gens here with pitiful 32gb storage - we've just had to offload apps, or plug them into AC and let that handle the updates. Security updates take priority.

 

If you use an MDM, it should be easy enough to remove the apps and then throw them back on? In our Meraki, I just remove them from the app group, install the update, and then add them back.

  • Like 3
Posted

I do understand your point.

 

However that means taking the majority of our ipads out of circulation- and it can be done in the summer.  But why upgrade to 26.xx if it is still doing 18. updates and can cope with that - the extra new apps get blocked by us anyway as they are not useful.

Posted

Ours just won't update due to lack of space. The users don't even notice any warnings etc. I plugged them one-by-one into the Apple Devices app to update them mainly over 1/2 term to 26.5 but it's a bit like painting the Forth Bridge: By the time all the 32GB ones are up to date a new update is released.

Posted
16 minutes ago, Scifigirl said:

I do understand your point.

 

However that means taking the majority of our ipads out of circulation- and it can be done in the summer.  But why upgrade to 26.xx if it is still doing 18. updates and can cope with that - the extra new apps get blocked by us anyway as they are not useful.

 

What MDM do you use? You should be able to lock to iOS 18.

Posted

We've just decommisioned over 35 iPads that were knocking about, they were no longer receiving security updates, some were the original iPads minis - they've now been blocked from joining our Wifi and have been handed out to departments that will use them just as cameras.

 

Does it not go against Cyber Essentials to be running hardware that cannot be patched?

Posted

probably does- and i am not getting into that conversation.  We don't have cyber essentials, and don't plan to as far as i am aware.  

 

these are mainly used for browsing and touch screen games so have no data on them - i have even disable the cameras to stop them from containing photos/data.  we just need them to keep running as we have no budget to replace- like everyone else.

Posted
23 minutes ago, Scifigirl said:

probably does- and i am not getting into that conversation.  We don't have cyber essentials, and don't plan to as far as i am aware.  

 

these are mainly used for browsing and touch screen games so have no data on them - i have even disable the cameras to stop them from containing photos/data.  we just need them to keep running as we have no budget to replace- like everyone else.

 

Whilst I sympathise, all of our "expired" iPads I'm sure departments would have loved to have kept going on the WiFi - but security should trump all "need".

 

Not having money should be no excuse to not follow standard security practices in this and other situations, you need to be careful as any compromise traced back to out of date hardware will fall on your lap as being responsible, unless of course you get things in writing from those above.

  • Like 3
Posted
32 minutes ago, Scifigirl said:

We don't have cyber essentials, and don't plan to as far as i am aware.  


You should seriously consider this. You have an obligation to ensure data is safe and Cyber Security is a key element of this.

  • Like 2
Posted

We keep track of all we can - and run to the standards we can without compromising the teaching and learning aspect of the school.

 

old iPads locked into guided access with just touch screen games on them or for very locked down browsing of sites (whitelisting on both the iPad and the filtering system) are what we can afford right now.  

 

Currently staff are being made redundant and benefits are being removed from staff due to the cuts in budgets- i don't feel out of line to say we will keep what we can working for as long as possible.

 

We are Keeping to as many standards as possible within our realm of influence and budgetary restraints.  As i said we don't plan on getting the paperwork but it doesn't mean we aren't doing all we can to ensure standars are followed.

 

I am updating- just only to 18.  whatever - the extras in 26 are not needed and just bloat space.  I am sorry if i did not make that clear with my question, but i do not want this to get off topic onto a discussion of cyber essentials please

Posted
2 minutes ago, Scifigirl said:

old iPads locked into guided access with just touch screen games on them or for very locked down browsing of sites (whitelisting on both the iPad and the filtering system) are what we can afford right now.  

 

This doesn't alleviate the Cyber risk.

  • Like 2
Posted

If there is no way to upgrade due to 32Gb (which i get 64gb is even a struggle now) i would do the following. mark them as EOL and not to be used. Explain to the powers at be the risks at play, if they don't care, you write it up and get them to sign it off saying they are responseable for any security breach due to the out of date OS. (9/10 they will say no and just buy new iPads) 

 

Rule 101 of IT. ALL* devices needs to have their security updates applied in a timely manner

 

*yes i know of certain air gapped machines that run a laser printer from the 1800s....

Posted

The answer isn't to block security updates. From your own description, you can run iPad OS 18. My suggestion is that you compromise on the number of installed apps - that's how you can keep the devices functional. 

Cyber security is a basic requirement that *does* come ahead of teaching and learning. Without it you can't keep your legal obligations for KCSIE and is essential to ensure your school doesn't become the next victim to a cyber attack.

It's equivalent to decommissioning PE equipment that doesn't pass safety tests or DT tools that are worn out. They probably still work and there's a high likelihood that no one will come to harm before the summer holidays and withdrawing them from service will impact teaching and learning. No responsible leadership team would take that risk and they should have the same attitude to cyber security.

  • Like 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...